Exploited Known exploited (KEV) Ransomware use CVE-2023-4966

The fix alone is not enough — every session had to be killed on Citrix NetScaler

Citrix NetScaler ADC and NetScaler Gateway Added to KEV Oct 18, 2023 Federal remediation due 2023-11-08

For the buffer overflow in Citrix NetScaler ADC and NetScaler Gateway, CISA required agencies to apply mitigations and to kill all active and persistent sessions. Where no mitigation was available, use of the product was to stop.

Key facts

  • CVE IDCVE-2023-4966
  • Affected (vendor / product)Citrix NetScaler ADC and NetScaler Gateway
  • CWECWE-119
  • ExploitationListed in CISA KEV (exploitation confirmed); also confirmed used in ransomware
  • Remediation due2023-11-08 (U.S. federal civilian agencies, BOD 22-01)

Key points

  • CVE-2023-4966 is a buffer overflow vulnerability in Citrix NetScaler ADC and NetScaler Gateway.
  • It allows sensitive information disclosure when configured as a gateway, such as a VPN virtual server, ICA proxy, CVPN or RDP proxy, or as an AAA virtual server.
  • The required action is to put the mitigations on and, on top of that, to end every session, live or persistent.
  • Where mitigations are unavailable, use of the product is to be discontinued.
  • Listed 18 October 2023 with a due date of 8 November, a window of twenty-one days; of the 1,579 entries without an article this site holds as of 2026-09-05, 602 (38.1%) carry the phrase discontinue use.

1Closing the hole does not bring back what left through it

The previous article followed an entry where an account created by an attacker outlived the fix, so compromise had to be determined. The same shape appears here, but what outlives the fix is different. Here it is sessions.

2Two things at once

The aspectA typical entryThis entry, NetScaler
What is askedApply mitigationsApply mitigations and kill all sessions
Why the fix falls shortThe flaw discloses sensitive information, which can sustain access afterwards
The alternativeDiscontinue use of the product where mitigations are unavailable
Configurations affectedVPN virtual server, ICA proxy, CVPN, RDP proxy, AAA virtual server

This flaw permits the disclosure of sensitive information. With what was disclosed, a path already established can remain usable after the flaw itself is closed. Killing the sessions is how that path is cut.

3An instruction joined by and

Of the 1,695 records this site holds as of 2026-09-05, those without an article1,579602 (38.1%) carry the phrase discontinue use
Of those, entries written as apply mitigations or else discontinue use252A standard pairing
This entryApply mitigations and kill all sessions, or discontinue useThe standard pairing with one clause added

The pairing apply mitigations or else stop using it appears on 252 entries and is one of the standard forms. This entry is that form with kill all sessions added to it. The departure from the standard is what tells you about the flaw.

4Twenty-one days

Listed 18 October 2023, due 8 November: twenty-one days, the most common window of all. Against the four days in the previous article that looks generous, yet more work is asked for. The length of the window and the weight of the work are set independently.

The next article takes up an entry that set an order for returning a device to service: hunt, remediate, then update.

Why it matters

Closing a vulnerability does not retrieve what escaped through it. Where the flaw discloses sensitive information, an established path can be followed afterwards, so the instruction adds killing every session to applying the mitigation. That the standard pairing, mitigate or stop using it, gains one extra clause is itself a statement about the nature of the flaw.

FAQ

Why kill the sessions as well?
Because the flaw discloses sensitive information, and what was disclosed can keep an established path usable after the flaw is closed.
Which configurations are affected?
Those set up as a gateway, meaning a VPN virtual server, ICA proxy, CVPN or RDP proxy, or as an AAA virtual server.
What if no mitigation is available?
Use of the product is to be discontinued.

Sources (primary)

This article is an independent organization based on the U.S. official data below. Always verify the exact, latest details and applicability with the official and vendor sources.

#Vulnerabilities#KEV#CISA#United States#Cybersecurity
Disclaimer: This site independently summarizes and classifies information based on official data sources. Always verify the latest and accurate information with the official sources. Content on finance, health, legal, and security is information, not advice. This site is not an official website of the U.S. government.